A portable version of OpenBGPD 6.5p1 is now available

OpenBSD developers have published the first stable update of the portable edition of the routing package OpenBGPD 6.5, which can be used in operating systems other than OpenBSD. Portions of code from the OpenNTPD, OpenSSH, and LibreSSL projects were utilized to ensure portability. In addition to OpenBSD, Linux and FreeBSD support has been declared. OpenBGPD has been tested on Debian 9, Ubuntu 14.04, and FreeBSD 12.

The development of OpenBGPD is being conducted with support from the regional internet registrar RIPE NCC, which is interested in making OpenBGPD functional for use on servers for routing at Internet exchange points (IXP) and in creating a full-fledged alternative to the package BIRD (among other open alternatives implementing the BGP protocol, the projects worth noting are FRRouting, GoBGP, ExaBGP and Bio-Routing).

In the development of OpenBGPD, the primary focus is on ensuring the highest level of security and reliability. Stringent checks are applied for all parameters, buffer boundary compliance control measures, privilege separation, and restriction of access to system calls. The syntax of the configuration definition language is also noted for its convenience, along with high performance and memory efficiency (for example, OpenBGPD can operate with routing tables containing hundreds of thousands of entries). The project supports most of the BGP 4 specifications and complies with RFC8212 requirements, but does not attempt to be all-encompassing and mainly ensures support for the most needed and widespread features.

Thanks to the support of RIPE NCC during the development cycles of OpenBSD 6.4 and 6.5, the OpenBGPD project has made significant strides. For instance, the following improvements have been made in release 6.5:

  • A simple rule optimizer has been added (merging filtering rules that differ only in filter sets);
  • The BGP MPLS VPN setup process has been changed;
  • IPv6 BGP MPLS VPN support has been added
  • The 'as-override' functionality has been implemented to replace the neighbor's AS with the local AS in paths;
  • The ability to match multiple communities in a single rule has been added;
  • New match attributes '*' 'local-as' and 'neighbor-as' have been added;
  • New commands for working with groups of neighboring autonomous systems have been added ('bgpctl neighbor group', 'bgpctl show neighbor group', 'bgpctl show rib neighbor group');
  • Work has been done to reduce memory usage;
  • Performance improved for large rule sets;
  • The ability to add networks to BGP VPN tables has been added to bgpctl.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster